Day 1: Tuesday, June 10, 2025

12:00 PM - 1:00 PM

Registration & Networking

 

Track 1

Track 2

 
1:00 PM - 3:00 PM
 

Workshop

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Workshop

The Current State and The Future of Operational Risk Management

Join us for an interactive workshop that delves into the current and future landscape of Operational Risk management. Drawing from Elena Pykhova’s best-selling book, the session will address key challenges faced by professionals and provide strategies for ongoing success. Topics include revitalizing risk implementations, mastering interconnected risk management, enhancing foresight, fostering strong risk cultures, and tackling emerging threats like third-party risks, cybersecurity, and resilience. Gain valuable insights on benchmarking, measuring maturity, and developing a future-focused roadmap for success.

 
3:00 PM - 3:30 PM

Break

 
3:30 PM - 4:30 PM
 

Workshop (continued)

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Workshop

Optimize your GRC Framework with AiSPIRE- What's New and What’s Next?

Optimize your GRC framework with AiSPIRE to unlock new possibilities in risk management. This session will highlight the latest advancements in AiSPIRE, showcasing how AI-driven solutions are transforming governance, risk, and compliance processes. Attendees will explore new features, capabilities, and best practices for leveraging AiSPIRE to enhance risk assessment, streamline compliance workflows, and improve data-driven decision-making. Discover what’s next in GRC innovation and how to stay ahead with cutting-edge AI tools for a future-proof framework.

 
4:30 PM - 5:30 PM
 

Workshop (continued)

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Workshop

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC highlights the latest advancements in MetricStream’s CyberGRC platform, designed to help organizations stay ahead of emerging cyber threats. This session will explore new features that enhance risk visibility, improve incident response, and streamline compliance with evolving cybersecurity regulations. Attendees will learn how MetricStream CyberGRC enables proactive cyber risk management, strengthens security frameworks, and ensures resilience in the face of increasingly sophisticated cyber risks.

 
5:30 PM - 7:00 PM

Drinks & Reception

 
 

Day 2: Wednesday, June 11, 2025

8:00 AM - 9:00 AM

Registration & Networking Breakfast

 
9:00 AM - 9:05 AM

Welcome Note

Introduction and Welcome

 
9:05 AM - 9:45 AM

Opening Keynote

Beyond Boundaries: Embracing the Next Frontier of GRC

 
9:45 AM - 10:30 AM

Keynote & Fireside Chat 

 
10:30 AM - 11:00 AM

CXO Panel

The Evolving Role of a Risk & Compliance Officer

As regulatory landscapes shift and businesses embrace digital transformation, the role of Chief Risk & Compliance Officers is rapidly evolving. Beyond traditional oversight, they now play a strategic role in embedding resilience, managing emerging risks, and leveraging technology for proactive compliance. This session explores how risk professionals can adapt to increasing expectations, harness AI and automation, and drive a culture of accountability, ensuring organizations remain agile in an ever-changing environment.

 
11:00 AM - 11:15 AM

Break

 
11:15 AM - 11:45 AM

Product Keynote

 
11:45 AM - 12:30 PM

Case Study

Nordea's GRC Journey with MetricStream

Nordea started the GRC journey in 2022 with the ambition to create one Integrated Risk Management Application (IRMA). With the point of departure to implement an enterprise wide GRC solution that would establish common risk processes across all lines of defence, Nordea have now created the foundation to embark on the next step of our GRC MetricStream journey. A journey that take outset in the existing GRC set up, but with the ambition to enable the business usage even more with the support from Artificial Intelligence. With the establishment of one data model we can now utilise date from several risk processes which open the door for even better business usage of our risk management tool.

 
12:30 PM - 1:00 PM

Expert Talk

AI GRC: Accelerating Growth & Innovation with Governance

Artificial Intelligence (AI) is rapidly transforming Governance, Risk, and Compliance (GRC) by automating processes, generating meaningful insights, and enhancing productivity. However, as AI adoption accelerates, organizations must navigate emerging risks such as security threats, ethical dilemmas, bias, disinformation, and social manipulation. GRC professionals must not only leverage AI to optimize risk management and compliance but also establish guardrails to ensure its responsible and ethical use across the enterprise. To fully harness AI’s potential, businesses need robust governance frameworks, proactive risk management, and strong compliance mechanisms that foster trust, accountability, and resilience.

 
1:00 PM - 2:00 PM

Networking Lunch

 

Track 1

Track 2

Track 3

 
2:00 PM - 2:40 PM
 

Panel

What’s Next for Operational Risk Management?

As the risk landscape evolves, operational risk management must adapt to new challenges, including emerging technologies, regulatory pressures, and dynamic market conditions. In this session, the panelists will explore what are the key changes expected in operational risk management, how to make operational risk more strategic and how to drive actional insights through emerging technologies like AI, automation and quantification. Join us to understand the practical strategies to elevate your ORM programs and build resilience while maintaining a competitive edge in a dynamic risk environment.

Expert Talk

Towards a Secure Cloud: Top Strategic Priorities for Cyber Risk Leaders

Towards a Secure Cloud examines the top strategic priorities for cyber risk leaders in mitigating risks related in cloud environments. This session will explore the unique challenges and risks cloud adoption presents, including data protection, compliance, threat mitigation and third-party governance. Attendees will gain insights into best practices for implementing effective risk management strategies, and navigating evolving regulatory landscapes. Discover the latest tools, frameworks, and approaches to manage cyber risks while ensuring resilience against emerging cyber threats.

Product Session

Begin Your Operational Resilience Journey with MetricStream

Begin Your Operational Resilience Journey with MetricStream guides organizations in building a strong foundation for resilience in the face of disruptions. This session will showcase how MetricStream’s solutions empower businesses to identify, assess, and mitigate risks while ensuring business continuity. Attendees will learn how to integrate resilience strategies into their operations, enhance crisis management capabilities, and drive proactive risk management. Discover how MetricStream’s approach enables organizations to thrive in an unpredictable and complex risk landscape.

 
2:40 PM - 3:20 PM
 

Expert Talk

The Future of Compliance is Automation

The Future of Compliance is Automation explores how automation is revolutionizing the compliance landscape. This session will focus on the role of advanced technologies like AI and machine learning in streamlining compliance processes, reducing manual efforts, and minimizing errors. Attendees will gain insights into how automated solutions are improving efficiency, ensuring continuous monitoring, and helping organizations stay ahead of regulatory changes. Discover the future of compliance and how to implement automation to drive a smarter, more agile approach.

Expert Talk

Towards a Secure Cloud: Top Strategic Priorities for Cyber Risk Leaders

Towards a Secure Cloud examines the top strategic priorities for cyber risk leaders in securing cloud environments. This session will explore the unique challenges cloud adoption presents, including data protection, compliance, and threat mitigation. Attendees will gain insights into best practices for ensuring cloud security, implementing effective risk management strategies, and navigating evolving regulatory landscapes. Discover the latest tools, frameworks, and approaches to safeguard cloud infrastructure and ensure resilience against emerging cyber threats.

Product Session

New Reports and Dashboards to Enhanced Risk Assessments: What’s New in MetricStream Risk Management

New Reports and Dashboards to Enhance Risk Assessments: What’s New in MetricStream Risk Management showcases the latest innovations in risk assessment capabilities. This session will explore new reports and dashboards that provide deeper insights, better visualization, and real-time tracking of risk metrics. Attendees will learn how these enhancements streamline risk assessments, improve decision-making, and help organizations identify and mitigate risks more effectively. Discover how MetricStream’s advanced features empower organizations to stay ahead of evolving risks and drive more informed risk management.

 
3:20 PM - 3:40 PM

Break

 
3:40 PM - 4:20 PM
 

Panel

Establishing a Strong Compliance Culture: Beyond the Corporate Compliance Code

A strong compliance culture goes beyond a mere tick in the box or having a written compliance code—it requires embedding ethical practices, accountability, and proactive risk management into an organization’s DNA. This session explores strategies to foster an environment where compliance is integral to decision-making, driven by leadership and embraced across all levels. Discover how to align organizational values with daily operations, leverage training and technology, and measure the impact of a truly effective compliance culture.

Panel

Adopting a Controls-Based Approach for Cyber Compliance and Resilience: From DORA to NIST and Beyond

Adopting a Controls-Based Approach for Cyber Compliance and Resilience explores how organizations can strengthen their cyber resilience by implementing a structured, controls-based framework. This session will cover key standards like DORA and NIST, highlighting how they guide cyber compliance and risk management. Attendees will learn how to align with these frameworks, enhance their controls environment, and ensure regulatory compliance while building robust cyber resilience. Gain insights on bridging compliance requirements with operational resilience in an evolving threat landscape.

Product Session

Level Up Your Compliance Posture with MetricStream’s All-New Compliance Management

Level Up with MetricStream’s All-New Compliance Management showcases the latest features designed to enhance compliance processes and drive greater efficiency. This session will explore how MetricStream’s advanced solutions streamline compliance tracking, automate workflows, and provide real-time visibility into regulatory requirements. Attendees will learn how to leverage these new capabilities to improve accuracy, reduce manual effort, and ensure proactive compliance. Discover how MetricStream’s innovative tools help organizations stay ahead of evolving regulations while mitigating compliance risks.

 
4:20 PM - 5:00 PM
 

Panel

The Journey Towards Operational Resilience: Key Priorities for Risk and Resilience Leaders

The Journey Towards Operational Resilience delves into the critical priorities for risk and resilience leaders as they navigate today's dynamic risk landscape. This session will explore strategies to build resilience across people, processes, and technology, ensuring organizations can withstand and recover from disruptions. Attendees will learn key insights on aligning risk management with business continuity, fostering a resilient culture, and adopting innovative approaches to safeguard operations in an increasingly uncertain world.

Panel

A CISO's Focus on Foundations for Success

A CISO's Focus on Foundations for Success explores the critical elements needed for a successful cybersecurity strategy. This session will discuss how Chief Information Security Officers can lay strong foundational frameworks in governance, risk management, and compliance to protect their organization’s digital assets. Attendees will gain valuable insights into building a resilient security posture, aligning security with business objectives, and fostering a culture of security awareness, all while ensuring long-term cybersecurity success.

Product Session

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC explores the latest updates to MetricStream's CyberGRC solution designed to combat evolving cyber threats. This session will highlight new features that enhance risk visibility, streamline incident response, and ensure robust compliance with the latest cybersecurity regulations. Attendees will learn how MetricStream CyberGRC empowers organizations to proactively manage cyber risk, strengthen their security posture, and remain resilient in the face of an increasingly complex threat landscape.

 
5:00 PM - 5:30 PM

GRC Journey Awards

Recognizing GRC Excellence: The GRC Journey Awards What does GRC excellence look like in action?

MetricStream will recognize key achievements of customers and partners in the field of governance, risk, and compliance management.

 
5:30 PM - 5:45 PM

Closing Keynote

 
5:45 PM - 7:45 PM

Drinks & Reception

 
 

Day 3: Thursday, June 12, 2025

8:00 AM - 9:00 AM

Registration & Networking Breakfast

 
9:00 AM - 9:05 AM

Welcome Note

Introduction and Welcome

 
9:05 AM - 9:45 AM

Opening Keynote

Shaping the Future of GRC with AI and Resilience

 
9:45 AM - 10:30 AM

Keynote & Fireside Chat

AI Regulatory Outlook: What’s Ahead and What to Expect?

While presenting unprecedented opportunities, advancement in AI also raises significant ethical, societal, and legal challenges. It is imperative to understand the key drivers shaping regulatory frameworks, including concerns around bias, transparency, accountability, and data privacy. Furthermore, the seminar will address the practical implications for businesses and organizations, exploring strategies for navigating the complex regulatory environment and ensuring responsible AI practices.

 
10:30 AM - 11:00 AM

CXO Panel

Managing Interconnected Risks: Why It Should Be a Boardroom Priority

In today’s complex business landscape, risks are no longer isolated—they are deeply interconnected, spanning cybersecurity, supply chains, regulations, and reputation. Boards must recognize that a siloed approach to risk management is no longer sufficient. This session explores why leaders must adopt a holistic risk strategy, enhance cross-functional collaboration, and leverage data-driven insights to anticipate and mitigate cascading threats, ensuring long-term resilience and sustainable business growth.

 
11:00 AM - 11:15 AM

Break

 
11:15 AM - 11:45 AM

Product Keynote

Riding the AI Wave: MetricStream AI Innovations and Beyond

 
11:45 AM - 12:30 PM

Case Study

Zurich Insurance's GRC Journey with MetricStream

How to Successfully Implement a GRC Solution in Less Than a Year? What are the absolute golden rules to follow to move from manual tasks to state-of-the-art GRC technology? How can you continue the journey to become best in class? How do you establish trust within the golden triangle of IT, GRC vendor, and business? Join this session to get answers to these questions and more.

 
12:30 PM - 1:00 PM

CXO Panel

Who's Responsible for Responsible AI?

While AI has been making inroads in our lives over the last decade, its use has been restricted to data scientists and AI specialists. But generative AI burst onto the scene with its Natural Language Processing capabilities, democratizing the power of AI. Today, enterprises and regulators are left scrambling to find a way to manage and govern the risks it poses even as adoption increases exponentially. Attend this session to understand the risks, responsibilities and rewards of enterprise AI initiatives.

 
1:00 PM - 2:00 PM

Networking Lunch

 

Track 1

Track 2

Track 3

 
2:00 PM - 2:40 PM
 

Panel

Unleashing the True Power of RCSAs through AI and Automation

Discover how AI and automation are revolutionising the Risk and Control Self-Assessment (RCSA) process, transforming it from a routine compliance exercise into a dynamic tool for proactive risk management. This session will explore practical strategies to enhance efficiency, improve accuracy, and uncover deeper insights through cutting-edge technology. Learn how organisations can harness AI to streamline assessments, reduce human error, and empower teams to focus on high-impact risk mitigation.

Panel

What’s Ahead for CyberGRC? Top Trends and Challenges to Tackle in 2025

What’s Ahead for CyberGRC? Top Trends and Challenges to Tackle in 2025 explores the evolving landscape of CyberGRC and the key trends that will shape risk management in the year ahead. This session will dive into emerging cyber risks, regulatory changes, and advancements in technology that impact governance, risk, and compliance. Attendees will gain insights into the most pressing challenges for CyberGRC in 2025 and strategies for staying ahead, ensuring stronger cybersecurity and compliance in a rapidly changing environment.

Product Session

Streamline Policy Governance with MetricStream’s AI-Powered Policy Management

Streamline Policy Governance with MetricStream’s AI-Powered Policy Management explores how AI-driven solutions are transforming policy management processes. This session will highlight how MetricStream’s advanced technology simplifies policy creation, approval, distribution, and compliance tracking, ensuring consistent governance across the organization. Attendees will discover how AI can automate policy reviews, improve alignment with regulatory requirements, and provide actionable insights to enhance decision-making. Learn how to implement AI-powered tools to drive greater efficiency and accuracy in policy governance.

 
2:40 PM - 3:20 PM
 

Expert Talk

Integrating Value into GRC – A Fresh Perspective

In today’s rapidly evolving business landscape, Governance, Risk Management, and Compliance (GRC) systems are often perceived as cumbersome, abstract, and disconnected from the core purpose of creating and preserving value. This session will challenge conventional approaches to GRC and present innovative, thought-provoking ideas to transform these systems into dynamic, value-driven frameworks that resonate with organizations and their people. Join this session to explore how we can make GRC exciting, impactful, and integral to the future of risk management.

Expert Talk

CyberGRC: A Connected, Continuous, Cognitive Strategy to Master IT and Cyber Risk

CyberGRC: A Connected, Continuous Strategy to Master IT and Cyber Risk focuses on adopting an integrated, continuous approach to managing IT and cyber risks. This session will explore how a connected strategy can streamline risk identification, assessment, and mitigation across the organization. Attendees will gain insights into leveraging real-time data, automated workflows, and continuous monitoring to enhance cybersecurity, ensure regulatory compliance, and strengthen overall resilience. Learn how to build a robust, adaptive CyberGRC framework for the future.

Product Session

Empower Auditors with Actionable Insights: What’s New in MetricStream Internal Audit

Empower Auditors with Actionable Insights: What’s New in MetricStream Internal Audit focuses on the latest innovations designed to enhance audit processes. This session will explore new features in MetricStream Internal Audit that provide auditors with real-time insights, data-driven analytics, and streamlined workflows. Attendees will learn how to leverage these capabilities to improve audit efficiency, enhance risk visibility, and drive more informed decision-making. Discover how MetricStream’s advancements are reshaping internal audits for greater effectiveness and impact.

 
3:20 PM - 3:40 PM

Break

 
3:40 PM - 4:20 PM
 

Panel

Transforming Your GRC Programs with AI innovations

Transforming Your GRC Programs with AI Innovations explores how organizations can revolutionize their governance, risk, and compliance (GRC) programs by incorporating AI-driven solutions. This session will highlight the latest AI innovations that enhance risk assessment, automate compliance processes, and improve decision-making. Attendees will gain insights on how AI can streamline workflows, improve accuracy, and help organizations stay ahead of regulatory changes. Discover practical strategies for integrating AI into your GRC framework for more efficient and effective risk management.

Panel

Simplifying Cyber Compliance, Controls, and Audits through a continuous and connected approach

Simplifying Cyber Compliance, Controls, and Audits through a Continuous and Connected Approach focuses on streamlining cybersecurity processes by integrating continuous monitoring, automated controls, and real-time audits. This session will explore how a connected approach enhances compliance efficiency, ensures up-to-date risk management, and reduces manual intervention. Attendees will learn how to implement a seamless, proactive framework that simplifies auditing and control activities, improves security posture, and ensures ongoing compliance with evolving regulations in a dynamic threat landscape.

Product Session

Optimize your GRC Framework with AiSPIRE- What's New and What’s Next?

Optimize your GRC Framework with AiSPIRE – What’s New and What’s Next? explores the latest enhancements to the AiSPIRE platform, designed to elevate your GRC capabilities. This session will showcase new features and innovations that empower organizations to streamline risk management, improve compliance, and enhance decision-making. Attendees will discover how AiSPIRE’s AI-driven tools are transforming GRC processes, and gain insights into future developments that will keep your organization ahead in an ever-evolving risk landscape.

 
4:20 PM - 5:00 PM
 

Panel

Driving Operational Efficiency and Business Growth through Collaborative Internal Audits

In today’s dynamic business landscape, internal audits are no longer just a compliance exercise—they are a strategic tool for driving operational efficiency and growth. This session explores how organizations can foster collaboration between audit, risk, and business teams to enhance transparency, identify opportunities, and streamline processes. Learn best practices for leveraging technology, data insights, and cross-functional partnerships to transform audits into a value-driven function that strengthens resilience and accelerates business success.

Panel

One View of Risk: Connected Cybersecurity and Operational Risk Management

One View of Risk: Connected Cybersecurity and Operational Risk Management explores the integration of cybersecurity and operational risk management to provide a unified approach to risk. This session will highlight the importance of connecting these two domains to gain a comprehensive understanding of risks across the organization. Attendees will learn how to leverage real-time data, enhance risk visibility, and ensure cohesive decision-making, ultimately improving resilience and enabling better risk mitigation in an increasingly complex and interconnected business landscape.

Product Session

Unlock the True Potential of Effective Third-party Risk Management: What’s New in MetricStream Third-Party Risk Management

Unlock the True Potential of Effective Third-Party Risk Management: What’s New in MetricStream Third-Party Risk Management highlights the latest advancements in managing third-party risks. This session will explore how MetricStream’s enhanced solutions provide better visibility, real-time monitoring, and deeper insights into third-party relationships. Attendees will learn how to improve risk assessment processes, strengthen vendor management, and ensure regulatory compliance. Discover new features and strategies that help organizations mitigate third-party risks and safeguard their operations in a connected world.

 
5:00 PM - 5:30 PM

CXO Panel

Top Emerging Risks on CXOs' Minds and Strategies to Manage Them

What's keeping the CXOs up at night? Join the session where the panel of C-level leaders discuss on the top emerging risks that are top-of-mind and critical for their business and understand their potential impact on your business. The session will also focus on insights and practical strategies to proactively address these emerging risks.

 
5:30 PM - 5:45 PM

Closing Keynote

 
5:45 PM - 7:45 PM

Drinks & Reception